Memory hook: Posture finds exposure; workload protection detects threats; prevention still needs correctly scoped policy.
Must remember
- Distinguish app registrations (application definitions) from enterprise applications/service principals (tenant instances). OAuth delegated/application permissions and consent have different implications. Review grants, publisher trust, owners and overprivileged roles; use PIM and Conditional Access where appropriate.
- Key Vault separates keys, secrets and certificates. Configure its authorisation model, network access, soft delete/purge protection and lifecycle deliberately. Rotation needs compatible clients and recovery planning. Defender for Key Vault and CSPM secret discovery provide different detection capabilities.
- Defender for Cloud CSPM assesses posture and attack paths; workload protection plans cover supported services. Enable the required plans and connectors rather than assuming every workload is protected by default. Regulatory-compliance views organise evidence, not automatic legal certification.
- For servers, use supported trusted-launch/secure-boot/vTPM/integrity features, encryption, JIT access and Bastion. Arc brings supported hybrid/multicloud resources into management; Defender for Servers supports vulnerability/EDR and agentless capabilities according to plan/configuration. Machine Configuration evaluates/enforces supported guest baselines.
- Protect containers with image/runtime assessment, registry restrictions, workload identity, Kubernetes RBAC/network controls and secure configuration. Secure Functions, Logic Apps and App Service using identities, authentication and network restrictions. API Management policies and WAF protect different application boundaries.
- Secure storage and SQL with identity/data permissions, firewalls/private endpoints, encryption, auditing and appropriate Defender plans. Network Manager/security admin rules, Firewall, Virtual WAN controls and Entra Private Access serve distinct access/inspection needs; verify effective rules and routes.
- EASM discovers externally visible assets/exposure; vulnerability management identifies supported weaknesses. Connect AWS/GCP environments through supported Defender connectors with scoped permissions. Remediation should prioritise exploitable paths and business impact, then verify the fix.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Find risky combinations of permissions and exposure | CSPM/attack-path analysis with workload context. |
| Limit administrative port exposure | JIT and controlled access such as Bastion. |
| Detect unexpected public assets | External Attack Surface Management. |
Traps
- Enabling one Defender plan does not enable all protection.
- Compliance score is not proof of complete security.
- A secret rotation can break clients if retrieval/cache behaviour is ignored.
Active recall
1. What differs between an app registration and a service principal?
The application definition versus its identity instance in a tenant.
2. Why review OAuth consent?
An application can receive significant delegated or application access independent of a user's ordinary resource workflow.
3. What does Arc add?
Supported management/governance integration for resources outside native Azure deployment.
4. Why combine posture and runtime evidence?
Exposure shows potential paths; runtime evidence shows observed behaviour and threats.
5. What should follow remediation?
Re-evaluation of effective access/configuration and confirmation that the application still operates safely.